Form specific notes:
B. This item is only required if there is an opt-in/opt-out available. If any of the purposes includes analysis that can be related to the individual user, or actions based on user history, or contact by any means, or the recipients include an organization other than the site collecting the information; then there should be a choice for the user to opt-in or opt-out of collection. If possible, the site should use opt-in vice opt-out because it gives the user more control of information.
C. The form should note optional and mandatory data. See Data Note 4 for a description of optional data.
D. The best way to notify users you have a privacy statement is to identify it at the point of collection.
E. The privacy statement or a statement related to the form must state when users should expect contact to occur and whether or not they have the option of not receiving this type of communication. If this contact information is shared with third parties you should tell the users they will receive communications from them.
F. If the form is posted to the same web site (vice another domain such as a third party credit card processor) then the data needs to be identified in the privacy policy. If the data is posted to a third party, then the privacy statement should provide information about who is getting the data.
G. This makes the information submitted public information and disclosure may increase their chance of receiving "spam" or unsolicited email. The site should warn users to be extra careful and to use their discretion when disclosing information online.
H. The page (at the point of data collection) must explicitly declare which organization is collecting the information.
Data specific notes:
3. Sharing information must be disclosed in the privacy policy.
4. Optional data is information that is not required for the action to be completed satisfactorily. That is, submitting a form with the data element empty will not result in an error and the action specified by the purpose of data collection will still be carried out satisfactorily. If the data is optional then it should indicate it is optional at the data collection point.
5. If Column 5 answer is "Yes" then the following applies:
| Column 6 should indicate users can edit/change information. |
| If column 3 indicates data is shared then users should have an opt-in/opt-out available (Form Note B). Failure to provide opt-in/opt-out will affect cookies. |
6. Users should have a mechanism to delete/deactivate/change personal information from the site's database by request or automatically using an account edit mechanism online. This statment should appear in the privacy policy. If the information collected is used to contact the individual then the mechanism should be provided when contact is made.
|